kadenca

legal · privacy policy

Kadenca — Privacy Policy

Version 1.2 — effective 10 September 2026

Kadenca is studio-management software operated by Srlaya Studio, Mgr. Swinkelsstraat 53, 5623 AP Eindhoven, Netherlands (KVK 42104493, BTW-id NL005496029B89) — "Srlaya", "we", "us".

This policy explains what we do with personal data in connection with the Kadenca website (kadenca.app) and the Kadenca platform, including each studio's app at <studio>.kadenca.app. Contact for any privacy matter: privacy@kadenca.app.


1. The two roles — please read this first

Kadenca is used by fitness, pilates and wellness studios to run their own businesses. That means personal data reaches us in two very different ways, and your rights are exercised in two different directions:

a) We are the controller for data about people we deal with directly: visitors to kadenca.app, people who email us, and the studios that subscribe (their owners and the staff who administer the account). Sections 2, 4–9 describe that.

b) We are a processor for everything a studio and its members put into the studio's own app — member profiles, bookings, attendance, memberships, payment records, signed documents. For that data the studio is the controller: it decides what is collected and why, and we act only on its instructions under the data-processing agreement in Annex A of our Terms. Section 3 describes that. If you are a member of a studio, your first point of contact is your studio, not us — we will refer your request to them.

2. What we process as controller

Website visitors. Kadenca.app sets no cookies, runs no analytics, and does not profile, track or advertise to anyone. Our servers keep short-lived technical logs (IP address, requested URL, timestamp, user agent, response status) to keep the service available and to investigate abuse and faults.

People who contact us. If you email us (for example hello@ or support@kadenca.app) we process your name, email address and whatever you choose to write, in order to answer you and to keep a record of the conversation.

Studio customers. For each subscribing studio we process the business contact details of its owner and administrators (name, email, phone), account credentials (passwords are stored only as scrypt hashes — never in readable form), the studio's configuration (name, locations, timezone, branding), billing and invoicing data, support correspondence, and an audit log of administrative actions taken on the account.

Signing up. When you create a studio at kadenca.app/signup — or, as an existing studio, accept a card-billing offer in the app's Settings — we record the studio name, your name and email, the chosen subdomain, and the version of our Terms you accepted with the time and IP address of that acceptance. The signup form is protected by Cloudflare Turnstile, which looks at your IP address and browser signals to tell people from automated abuse; that check is the only third-party request the website makes (see section 9).

Card billing. If your studio pays its Kadenca subscription by card, you enter your name, email, billing address, VAT ID and card on a checkout page hosted by Stripe (Stripe Payments Europe, Limited, Dublin, Ireland). Stripe processes that payment data as an independent controller under the Stripe Privacy Policy; we receive back and store only Stripe's customer and subscription identifiers, the subscription's status and dates, and the invoices Stripe issues on our behalf. We never see or store your card number.

Card payments from your members (Stripe Connect). If your studio activates card payments, we create a Stripe account in your studio's name and Stripe collects, in its own onboarding, the business and personal data it needs to verify your studio and pay you out. When you provide personal data in connection with Kadenca, Stripe receives that personal data and processes it in accordance with Stripe's Privacy Policy. We store the account's identifier and its verification status.

Prospective customers. If you contact us about a subscription, we keep that correspondence and the details you provide for as long as the conversation is live and for a reasonable period afterwards.

3. What we process on behalf of studios

When a studio runs its app, the following categories of data about its members are stored and transmitted through our systems, strictly to provide the service: identification and contact data (name, email, phone), membership and booking records (packages, credits, class bookings, attendance, waitlists), payment records (invoice and payment-slip data and, where the studio has activated card payments, the member's name, email and amount passed to Stripe on the studio's own Stripe account together with Stripe's payment identifiers — the platform stores no card numbers), push-notification device tokens where the member has enabled notifications in the mobile app, signed documents (waivers, consents, including guardian consents for minors), uploaded images (profile photo, the studio's logo), and any notes the studio's staff choose to record about a member, which may include health-related information the member gave their studio.

We do not use this data for our own purposes. We do not sell it, mine it, train models on it, or use it to contact members other than to deliver the messages the studio's app sends on the studio's behalf (booking confirmations, reminders, account emails). Each studio's data lives in its own separate database and file storage, isolated from every other studio.

4. Legal bases (as controller)

WhatBasis
Providing the service to a subscribing studioPerformance of a contract (Art. 6(1)(b))
Answering enquiries and support requestsLegitimate interest / pre-contractual steps (Art. 6(1)(f), (b))
Keeping the platform secure, logs, abuse preventionLegitimate interest (Art. 6(1)(f))
Invoicing and statutory accounting recordsLegal obligation (Art. 6(1)(c))

5. Who else is involved

We keep the vendor list deliberately short. Each of these processes data only to run the service, under a data-processing agreement:

ProviderPurposeLocation
RenderApplication hosting and the disk holding studio databasesFrankfurt, Germany (EU)
CloudflareDNS, TLS, and email forwarding for our own addresses; encrypted backup storage (R2, EU jurisdiction); Turnstile bot protection on the signup formEU
Resend (Plus Five Five, Inc., San Francisco, USA)Sending transactional email from the EU region (eu-west-1, Ireland); Resend stores email metadata and delivery logs in the USA under the EU Standard Contractual ClausesEU sending; metadata in the USA
Amazon Web Services (SES)Email delivery infrastructure (underlying Resend, and as fallback when used directly)EU (Ireland via Resend; eu-central-1 Frankfurt when direct)
Stripe (Stripe Payments Europe, Limited, Dublin, Ireland)Subscription billing of card-billed studios, and card payments from members on each studio's own Stripe account — in both cases Stripe acts as an independent controller for the payment dataEU
Google Firebase Cloud Messaging / Apple Push Notification serviceDelivering push notifications to the mobile app: the device token and the notification text pass through Google (and, on iOS, Apple)EU/USA under the providers' standard safeguards
SentryError diagnostics (configured without attaching personal data; enabled per deployment)EU

We otherwise disclose personal data only where we must: to a competent authority when legally required, or to our professional advisers under confidentiality. We do not sell personal data, and we never share one studio's data with another.

6. Where your data is stored

Hosting, databases, backups and email sending are within the EU/EEA (Frankfurt for the application and databases; Ireland for email sending; EU jurisdiction for backups). Two exceptions: Resend keeps email metadata and delivery logs in the USA, and push notifications pass through Google's and Apple's delivery services — both under the European Commission's Standard Contractual Clauses or an equivalent Art. 46 safeguard. Stripe processes payment data under its own agreements and safeguards. Some of the other vendors above are US-headquartered companies operating EU infrastructure; where any support access from outside the EEA is possible, it is covered the same way. We will not move the processing of studio data outside the EEA without notice and an appropriate safeguard.

7. How long we keep things

8. Your rights

Under the GDPR you may request access to your personal data, correction, erasure, restriction, portability, and you may object to processing based on legitimate interest. Where processing relies on consent, you may withdraw it at any time.

You may also complain to a supervisory authority. Ours is the Dutch DPA — Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl); you may equally complain to the authority where you live, for example AZOP in Croatia.

9. Cookies, storage, and fonts

We use no cookies — none for tracking, none for analytics, none at all. There is therefore no cookie banner, because there is nothing to consent to.

The app does use your browser's own storage to work: a session token in sessionStorage that keeps you signed in and disappears when you close the tab, and a small branding cache in localStorage so your studio's name and colours appear instantly on the next visit. Neither is shared with anyone, and clearing your browser storage removes both.

The website serves its two typefaces from our own servers and makes no third-party requests — no fonts, no scripts, no embeds — with one exception: the signup form loads Cloudflare's Turnstile challenge to keep bots out (section 2). Stripe's checkout and billing pages are Stripe's own sites, reached by a link.

10. Security

TLS everywhere; each studio's data in a separate database and file store; passwords stored as scrypt hashes; access tokens scoped per studio; role-based authorisation enforced on the server; daily encrypted (AES-256-GCM) off-site backups; an append-only audit log of state-changing actions; and least-privilege operator access — a single named operator. No security is absolute, but we would rather be plain about what we do than vague.

11. Minors

Studios may serve members under 18. Where they do, the studio is responsible for obtaining guardian consent; the platform provides a guardian-consent flow and stores the resulting record for the studio. We do not knowingly process children's data for any purpose of our own.

12. Changes

If we change this policy we will publish the new version here with a new effective date, and — for changes that matter to subscribing studios — notify them by email at least 30 days in advance.

13. Contact

Srlaya Studio · Mgr. Swinkelsstraat 53, 5623 AP Eindhoven, Netherlands · KVK 42104493 · privacy@kadenca.app